by
Justin Krentz, Vertilocity
| August 20, 2026
For CPA firms, trust has always been the foundation of every client relationship. Clients rely on their accounting professionals to safeguard some of their most sensitive financial and personal information. While that responsibility has traditionally centered around ethics and confidentiality, today it increasingly includes cybersecurity.
The reality is that cybercriminals aren't just targeting large corporations anymore. Small and mid-sized CPA firms have become attractive targets because they maintain extensive financial records, tax documents, payroll information and personal identifiable information — all of which are valuable on the black market.
The good news is that improving cybersecurity doesn't require every firm to become an IT expert. It starts with understanding a few practical best practices that significantly reduce risk for yourselves and your clients. Here are some considerations:
- Your people are your first line of defense. Technology plays an important role, but many successful cyberattacks begin with a simple email. Phishing attempts have become increasingly sophisticated, often appearing to come from clients, vendors or even internal staff. Regular cybersecurity awareness training helps employees recognize suspicious emails, unexpected attachments and fraudulent requests for sensitive information. Just as importantly, firms should foster a culture where employees feel comfortable asking questions before clicking or responding.
- Strong passwords are no longer enough. If your firm isn't already using multi-factor authentication (MFA) wherever possible, it should be a priority. MFA requires users to verify their identity with a second factor, such as a code on their phone, in addition to a password. Even if a password is compromised, MFA can prevent unauthorized access to email, tax software, cloud applications, and client files.
- Limiting access to sensitive information is mandatory. Not every employee needs access to every file. Applying the principle of least privilege means individuals only have access to the systems and client information necessary to perform their jobs. Reviewing user permissions periodically, especially after promotions, role changes or employee departures, helps reduce unnecessary exposure.
- Keeping systems current is a priority. Software updates may seem inconvenient, but they're one of the simplest ways to protect your firm. Many updates include security patches that address newly discovered vulnerabilities. Whether it's Windows, Microsoft 365, tax software or other business applications, timely updates reduce opportunities for attackers to exploit known weaknesses.
- Preparing for the unexpected is required. No organization believes it will experience a cyber incident until it happens. That's why backups and an incident response plan are critical. Backups should be tested regularly to ensure they can actually be restored. Equally important, firms should have a documented plan outlining who should be contacted, how systems will be secured and how clients will be informed if an incident occurs. Having a plan in place allows organizations to respond calmly rather than react under pressure.
- Cybersecurity is an ongoing business process. One of the biggest misconceptions is that cybersecurity is a one-time project. In reality, new threats emerge constantly, and firms should periodically evaluate their security posture, review policies and reassess risks as technology and business needs evolve.
As the profession continues to embrace cloud technology, remote work and digital collaboration, cybersecurity becomes less of an IT initiative and more of a business responsibility shared across the entire organization. Firms don't need to be perfect, but they do need to be intentional. By focusing on practical, proven best practices and making cybersecurity part of everyday operations, CPA firms can better protect their clients, their reputation and the future of their business.